mirror of
https://github.com/ipxe/ipxe
synced 2026-10-07 15:05:42 +03:00
6f1646d7bd7aca1acec2602054006e6e73faa03d
The cipher specifications are currently modelled as an active cipher specification that corresponds to the cipher currently in use by the secure channel abstraction, and a pending cipher specification that corresponds to the cipher that will be swapped in after the next ChangeCipherSpec. This design reflects the wording of RFC 2246 through to RFC 5246: "there are always four connection states outstanding: the current read and write states, and the pending read and write states". This model does not map well to TLS version 1.3, with its multiple phases of traffic secrets and somewhat idiosyncratic choices of transcript boundaries. The client Finished message is a particular problem: the client application traffic secret must be calculated after constructing the client Finished verify_data but before adding the client Finished to the transcript digest (i.e. before encrypting it with the client handshake traffic keys). This is an irritating asymmetry with the server application traffic secret, which may be calculated cleanly after the server Finished message has been added to the transcript digest. Switch to a model in which only the active cipher specification exists, and always corresponds to the cipher currently in use by the secure channel abstraction. Move the record sequence number to become part of the cipher specification, so that the sequence number reset logic can be shared between the transmit and receive paths. Signed-off-by: Michael Brown <mcb30@ipxe.org>
iPXE network bootloader
iPXE is the leading open source network boot firmware. It provides a full PXE implementation enhanced with additional features such as:
-
boot from a web server via HTTP or HTTPS,
-
boot from an iSCSI, FCoE, or AoE SAN,
-
control the boot process with a script,
You can use iPXE to replace the existing PXE ROM on your network card, or you can chainload into iPXE to obtain the features of iPXE without the hassle of reflashing.
iPXE is free, open-source software licensed under the GNU GPL (with some portions under GPL-compatible licences).
You can download the rolling release binaries (built from the latest commit), or use the most recent stable release.
For full documentation, visit the iPXE website.
Languages
C
98.5%
Assembly
0.6%
Python
0.3%
Perl
0.3%
Makefile
0.2%